Method and device for managing integrity of executable file of Linux system

By setting and monitoring the integrity tag attributes and data information database of executable files in the Linux system, the problem of failure to effectively manage program file integrity at the operating system level in the prior art is solved, real-time and efficient integrity management of the executable files in the Linux system is realized, and the security and efficiency of the system are improved.

CN120197230APending Publication Date: 2025-06-24KYLIN CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510267570.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The prior art fails to effectively manage the integrity of program files at the operating system level, and the existing measurement and verification methods are not efficient and have low fault tolerance.

Method used

By setting the integrity marking attributes of the executable file in the Linux system, establishing an integrity data database, monitoring the file write operation events, and updating the integrity marking and data database in real time, real-time monitoring and efficient verification of the file integrity status can be achieved.

Benefits of technology

Real-time efficient integrity management of Linux system executable files, improve the efficiency of file integrity checksum management, and enhance the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197230A_ABST
    Figure CN120197230A_ABST
Patent Text Reader

Abstract

The invention provides an integrity management method for an executable file of a Linux system, which comprises the following steps of: S1, initialization: setting an integrity mark attribute of the executable file, and establishing an integrity data information base of the executable file; s2, integrity monitoring: monitoring a write operation event of an executable file in a system kernel, and automatically changing the file integrity mark when the file is modified; and S3, integrity synchronization: sending a synchronization notice, and updating the integrity data information base of the executable file in a linkage manner. According to the method, a real-time and efficient file integrity measurement verification mechanism can be provided, and the file integrity verification and management efficiency is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer technology, and particularly relates to a method and device for managing the integrity of executable files in a Linux system. Background Art

[0002] With the popularization of computers, people obtain information and conduct various activities through computers and the Internet every day. Information technology has become an inalienable part of people's lives. However, the computer and cyberspace are not always secure, bringing huge security threats while bringing convenience to people. Illegal or malicious codes such as viruses and Trojans attempt to attack the system and enter the system illegally by tampering with or replacing system program files. A reliable, efficient, and real-time integrity measurement and verification mechanism is needed to ensure the security and reliability of operating system application programs in real time.

[0003] Trusted Computing (TC) is a technology promoted and developed by the Trusted Computing Group (TCG) (formerly known as TCPA). One of the core goals of trusted computing is to ensure the integrity of systems and applications, so as to determine that the system or software runs in the trusted state expected by the design goal. Adding trusted verification to the operating system and program files can reduce the possibility of being threatened due to the use of unknown or tampered program files.

[0004] Trusted computing mainly realizes the guarantee of the integrity of systems and applications through measurement and verification technologies. Measurement is to collect the status of the application software to be detected, and verification is to compare the measurement result with the expected measurement value to see if they are consistent. If they are consistent, it means the verification passes; if they are inconsistent, it means the verification fails.

[0005] There are certain deficiencies in the existing trusted computing methods, which are described as follows:

[0006] (1) The measurement of trusted computing is the measurement method for the trusted startup and boot process, which realizes the security measurement of the hardware firmware and does not involve the management of the integrity value of the program files at the operating system layer.

[0007] (2) The measurement and verification method of trusted computing is to compare hash values for verification. The verification process needs to collect the file hash value in real time and compare it with the whitelist database, and its integrity verification efficiency is not high.

[0008] (3) The measurement and verification of trusted computing monitor the file integrity in real time by monitoring the modification of the file integrity information. The error tolerance rate is low, and the file information is entered through the database, and the efficiency of the subsequent integrity measurement and verification is not high enough. Summary of the Invention

[0009] The purpose of the present invention is to provide a method and device for managing the integrity of executable files in a Linux system, provide a real-time and efficient file integrity measurement verification mechanism, and greatly improve the efficiency of file integrity verification and management.

[0010] In order to achieve the above object, the technical solution of the present invention is as follows:

[0011] A Linux system executable file integrity management method, comprising:

[0012] S1. Initialization: setting the integrity mark attribute of the executable file and establishing the integrity data information library of the executable file;

[0013] S2. Integrity monitoring: monitoring the write operation events of the executable file in the system kernel, and automatically changing the file integrity mark when the file is modified;

[0014] S3. Integrity synchronization: Send synchronization notifications to jointly update the integrity data information library of the executable file.

[0015] Furthermore, the method for setting the integrity mark attribute of the executable file in step S1 includes: recording the integrity mark of the executable file in the extended attribute inode node of the file.

[0016] Furthermore, in step S2, the method for monitoring the write operation event of the executable file includes: adding a hook function to the write operation function of the file in the Linux system, implementing a file integrity check in the hook function, and determining whether the file integrity has changed.

[0017] Furthermore, in step S3, the synchronization notification passes the message from the kernel to the application layer through the intra-kernel and extra-kernel communication mechanism.

[0018] The present invention also proposes a Linux system executable file integrity management device, comprising:

[0019] Initialization module: sets the integrity mark attribute of the executable file and establishes the integrity data information library of the executable file;

[0020] Integrity monitoring module: monitors the write operation events of executable files in the system kernel, and automatically changes the file integrity mark when the file is modified;

[0021] Integrity synchronization module: sends synchronization notifications and updates the integrity data information library of executable files in a linked manner.

[0022] Furthermore, the initialization module includes: recording the integrity mark of the executable file in the extended attribute inode node of the file.

[0023] Further, the integrity monitoring module includes: adding a hook function to the file write operation function in the Linux system, and implementing file integrity check in the hook function to determine whether the file integrity has changed.

[0024] Furthermore, in the integrity synchronization module, the synchronization notification passes the message from the kernel to the application layer through the in-kernel and out-of-kernel communication mechanism.

[0025] The present invention also provides a computer-readable storage medium, which stores a computer program for executing the above-mentioned Linux system executable file integrity management method.

[0026] The present invention also provides a computer program product, including a computer program, which implements the above-mentioned Linux system executable file integrity management method when executed by a processor.

[0027] Compared with the prior art, the present invention has the following beneficial effects:

[0028] 1) The present invention sets a file integrity mark, and the security mark is dynamically linked with the file write operation event, which can represent the file integrity status information in real time, providing an efficient comparison scheme and determination basis for file integrity verification;

[0029] 2) The present invention sets a synchronization update mechanism, and the integrity database of the file is synchronized and updated in real time with the file integrity mark, providing unified management data for system file integrity management. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 is a schematic diagram of the principle of an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0031] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0032] The present invention will be specifically described below with reference to specific embodiments and the accompanying drawings:

[0033] The design idea of the present invention is to set and link the security mark and integrity database of the executable file, and synchronously update the file integrity measurement information.

[0034] Based on the above design idea, this embodiment proposes a Linux system executable file integrity management method, which sets a file initialization module, an integrity monitoring module, and an integrity synchronization module, as Figure 1 shown, and the specific implementation process is as follows:

[0035] 1. Initialization module: The initialization module sets the integrity mark attribute of the executable file at the Linux system application layer and establishes an executable file integrity data information library;

[0036] The integrity mark of the executable file is recorded in the file's extended attribute inode node as a common Linux file system attribute; the integrity mark has three states, unset (00), legal (10), and tampered (11); the change of the integrity mark does not distinguish between different modification situations, and any modification behavior will cause the integrity mark to change to 11.

[0037] This embodiment marks the integrity of the file in real time by executing the integrity mark of the file. When the integrity monitoring module finds that the file has changed from the kernel, it changes the mark state to 11 and then notifies the application layer to synchronously update the database.

[0038] 2. Integrity monitoring module: The integrity monitoring module implements the linkage function between the write operation events of executable files and file attributes and the integrity mark. When the file or file attribute triggers a write operation event, the integrity mark of the file will be automatically changed, and then a synchronization event notification will be sent to the integrity synchronization module.

[0039] The integrity monitoring module is a kernel module that is set in the Linux system kernel. It achieves integrity by monitoring the file read and write access points of the file system. When a file is modified (triggering write operation events of files, file attributes, and file information, all write operations are recorded in real time), the module automatically modifies the status value of the file's integrity mark.

[0040] In this embodiment, a hook function is added to the file system write operation function, and the file read and write access point is set through the hook function. The file integrity check is implemented in the hook function, and the hash value verification method or other integrity check methods can be used. When an application (service) calls the write operation function to write an executable file or file attribute, the hook function will inevitably be called, and the hook function will be executed to determine whether the file integrity has changed (whether it has been modified), and the status value of the corresponding integrity mark will be changed synchronously.

[0041] 3. Integrity synchronization module: After receiving the synchronization event notification, the integrity synchronization module will update the file integrity data information library content in a linked manner to ensure that the information of the two is synchronized.

[0042] The integrity synchronization module is divided into two parts. One part is in the Linux system kernel, which receives the synchronization event notification sent by the integrity monitoring module and sends synchronization messages to the other part through the in-kernel and out-of-kernel communication mechanisms (such as sys file system, proc file system, netlink, etc.). The other part is in the Linux system application layer, which is used to receive synchronization messages and perform operations on the integrity database of file data information.

[0043] The integrity database of file data information can be used for:

[0044] 1) Unified viewing of the status values of executable file integrity tags;

[0045] 2) After an executable file is damaged, some data can be restored through the backup and restoration function. According to the integrity database of file data information, the status values of the integrity tags of the restored executable files can be re-initialized.

[0046] 3) During file integrity verification, when the status value of the integrity tag is 11, the integrity information of the file can be more accurately determined by comparing with the integrity database of file information again. This is to prevent scenarios where the integrity database of file data information in the application layer is not synchronized in time, such as kernel panic, synchronization service stop or failure, high CPU usage, etc. When it is found that the file integrity tag value is 10 (i.e., it means legal), the verification directly passes the check; when the tag value is incorrect, the integrity check can be determined by comparing the file hash value and matching the integrity database of file data information.

[0047] The key points of the method described in this embodiment are:

[0048] 1) File integrity security tags. The security tags are dynamically linked with file write operation events and can represent file integrity status information in real time, providing an efficient comparison scheme for file integrity verification;

[0049] 2) Synchronous update mechanism. The integrity database of file information and file tags are synchronously updated in real time, providing unified management data for system file integrity management.

[0050] The above-described embodiments are only the preferred embodiments of the present invention and are only used to help understand the method and its core idea of the present application. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.

Claims

1. A method for managing the integrity of executable files in a Linux system, characterized in that: include: S1. Initialization: setting the integrity mark attribute of the executable file and establishing the integrity data information library of the executable file; S2. Integrity monitoring: monitoring the write operation events of the executable file in the system kernel, and automatically changing the file integrity mark when the file is modified; S3. Integrity synchronization: Send synchronization notifications to update the integrity data information library of executable files in a linked manner.

2. The Linux system executable file integrity management method according to claim 1, characterized in that: The method for setting the integrity mark attribute of the executable file in step S1 includes: recording the integrity mark of the executable file in the extended attribute inode node of the file.

3. The Linux system executable file integrity management method according to claim 1, characterized in that: In step S2, the method for monitoring the write operation event of the executable file includes: adding a hook function to the write operation function of the file in the Linux system, implementing a file integrity check in the hook function, and determining whether the file integrity has changed.

4. The Linux system executable file integrity management method according to claim 1, characterized in that: In step S3, the synchronization notification passes the message from the kernel to the application layer through the intra-kernel and extra-kernel communication mechanism.

5. A Linux system executable file integrity management device, characterized in that: include: Initialization module: sets the integrity mark attribute of the executable file and establishes the integrity data information library of the executable file; Integrity monitoring module: monitors the write operation events of executable files in the system kernel, and automatically changes the file integrity mark when the file is modified; Integrity synchronization module: sends synchronization notifications and updates the integrity data information library of executable files in a linked manner.

6. The Linux system executable file integrity management device according to claim 5, characterized in that: The initialization module includes: recording the integrity mark of the executable file in the extended attribute inode node of the file.

7. The Linux system executable file integrity management device according to claim 5, characterized in that: The integrity monitoring module includes: adding a hook function to the write operation function of the file in the Linux system, implementing the file integrity check in the hook function, and determining whether the file integrity has changed.

8. The Linux system executable file integrity management device according to claim 5, characterized in that: In the integrity synchronization module, the synchronization notification passes the message from the kernel to the application layer through the intra-kernel and extra-kernel communication mechanism.

9. A computer-readable storage medium storing a computer program, characterized in that: The computer program is used to execute the Linux system executable file integrity management method as described in any one of claims 1-4.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for managing the integrity of executable files in a Linux system as described in any one of claims 1 to 4 is implemented.